Privacy Policy
Last updated Jul 27, 2026
This Privacy Policy explains how Progma, Inc. ("Progma", "we", "us", or "our") handles personal data in connection with our programming-education platform and related services (the "Service"). We are committed to handling personal data in accordance with the Philippine Data Privacy Act of 2012 (Republic Act No. 10173) and its implementing rules and regulations, and—where applicable—other data-protection laws.
Placeholder — confirm with counsel and your Data Protection Officer: effective date, the registered company name, your designated Data Protection Officer (DPO) and contact details, retention periods, and any cross-border transfer mechanisms.
1. Our role: controller and processor
Progma operates in two capacities:
- As a personal information controller for data we determine the purposes of—such as account and billing administration, prospect/lead inquiries, and support.
- As a personal information processor for personal data that an institution provides or directs us to process on its behalf (for example, student and teacher records and code submissions). In that case, the institution is the controller and its instructions govern. See the Data Processing Agreement.
2. Personal data we collect
Depending on your role and how the Service is used, we may collect:
- Account data: name, email address, email-verification status, role, institution membership, profile image/avatar, time zone, and last-login time.
- Authentication and session data: credentials (stored in hashed form), single sign-on identifiers and tokens (for example, Google OAuth), session identifiers, IP address, and device/browser (user-agent) information.
- Two-factor authentication data: whether two-factor authentication is enabled on your account and, if you enable it, the shared secret used by your authenticator app and your one-time backup codes. Both are stored encrypted (not hashed, because the Service must be able to read them to verify a code). We also record the number of consecutive failed verification attempts and any temporary lockout time, so that repeated guessing of your code can be blocked.
- Security and audit records: an append-only log of security-relevant account events — account creation, profile and status changes, role grants and revocations, email changes, two-factor authentication being enabled, disabled, or reset, backup codes being regenerated, and password changes — together with who performed the action and when. This log records the fact that a password was changed; it never stores the password itself or any hash of it.
- Institution and course data: institution membership, course enrollments, academic terms, and class records.
- Learning data: activities, submissions (including submitted source code and attempt data), automated grading results, and feedback.
- Billing and contact data: billing-contact details, quotation requests and estimated seat counts, subscriptions, invoices, and payment records.
- Prospect/lead data: information submitted through our public "Get Started" inquiry form, such as organization name, contact name, email, phone, estimated seat counts, and message content.
- AI-interaction data: prompts and content you submit to AI-assisted features and your saved AI preference rules.
- Support data: information you provide when you contact us.
3. Children's and student data
The Service is used by educational institutions and may be used by students who are minors. Where students are minors, institutions are responsible for obtaining any consents required under applicable law (including from parents or legal guardians where required) and for establishing the lawful basis for processing. We process student data on behalf of the institution and in accordance with the Data Processing Agreement.
4. How we use personal data
We use personal data to:
- provide, operate, secure, and support the Service;
- authenticate users and maintain account and session security;
- execute and grade code submissions and deliver feedback;
- operate AI-assisted features you choose to use;
- administer quotations, subscriptions, invoices, and payments;
- respond to inquiries submitted through our public forms and to support requests;
- communicate service, security, and billing notices; and
- comply with legal obligations and enforce our Terms.
When a security-relevant change is made to your account — two-factor authentication being enabled, disabled, or reset, backup codes being regenerated, or your password being changed — we send a notice to the account's own email address so that a change you did not make does not go unnoticed. These notices are transactional rather than marketing, are sent on the basis of our legitimate interest in securing accounts, and deliberately contain no links: a message warning you about account compromise should never be indistinguishable from a phishing attempt.
5. Legal bases
Where the Data Privacy Act or other law requires a legal basis, we rely on one or more of: the performance of a contract; compliance with a legal obligation; our legitimate interests (such as securing the Service); and consent where required. For data we process on behalf of an institution, the institution is responsible for the legal basis.
6. How we share personal data
We do not sell personal data. We share personal data with:
- Sub-processors and service providers that help us operate the Service (for example, hosting, database, code execution, AI, and email providers). See our Sub-processors list.
- The relevant institution, for data concerning its members.
- Authorities and others where required by law, to protect rights and safety, or in connection with a corporate transaction, subject to appropriate safeguards.
7. International transfers
Some sub-processors may process data outside the Philippines. Where personal data is transferred across borders, we take steps intended to ensure an adequate level of protection consistent with applicable law.
8. Retention
We retain personal data for as long as needed to provide the Service, comply with legal, tax, and accounting obligations (including invoicing records), resolve disputes, and enforce our agreements. For data processed on behalf of an institution, retention and deletion follow the institution's instructions and the Data Processing Agreement. Some records are soft-deleted (excluded from normal use) before permanent deletion.
9. Your rights
Subject to applicable law, data subjects may have rights to be informed, to access, to object, to rectify, to erase or block, to data portability, to lodge a complaint, and to damages. To exercise rights, contact us at support@progma.app. If your data is processed by Progma on behalf of an institution, we may direct your request to that institution.
Under the Data Privacy Act, you also have the right to file a complaint with the National Privacy Commission (NPC) of the Philippines.
10. Security
We maintain technical and organizational measures designed to protect personal data, including access controls, tenant isolation between institutions, encryption in transit, and audit logging of sensitive actions. Two-factor authentication is available for accounts that sign in with a password, and is required for Progma platform administrators. No method of transmission or storage is completely secure. To report a security concern, see our Security & Responsible Disclosure page or email security@progma.app.
11. Cookies
We use cookies and similar technologies, primarily for authentication and session management. See our Cookie Policy.
12. Changes to this Policy
We may update this Privacy Policy from time to time. Material changes will be indicated by updating the "Last updated" date and, where appropriate, by additional notice.
13. Contact us
For privacy questions or to exercise your rights, contact:
- Email: support@progma.app
- Mail: Progma, Inc., Banilad, Cebu City, Cebu, 6000, Philippines